Yapme

Privacy Policy

Last updated: 23 July 2026

1. About This Policy

This Privacy Policy explains how Chidurala Technologies ("we", "us", "our") collects, uses, and discloses personal information when you use the Yapme mobile application ("Yapme" or "the App"). It is written in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using Yapme, you agree to the collection and use of your information as described in this Policy. If you do not agree, please do not use the App.

2. About Us

Yapme is operated by Chidurala Technologies, an ASIC-registered sole trader based in Parramatta, New South Wales, Australia.

Contact for privacy matters: privacy@yapme.com.au

3. Information We Collect

a) Account information

When you create an account, we collect:

  • Your email address — used to verify your identity and deliver account-related communications.
  • Your username — a unique handle you choose. It does not need to be your real name.

We do not collect your real name, date of birth, phone number, or profile photo.

Your password is processed and stored by our authentication provider, Supabase (see Section 6). We never store or have access to your plaintext password.

b) Post content

When you post a yap, we collect the text content of that post (up to 100 characters). All posts are deleted from our servers after 24 hours. Replies are deleted when their associated post is deleted.

c) Approximate location

When you open Yapme, the App requests your approximate location from your device to show you posts from people nearby. Specifically:

  • We request the lowest available location accuracy from your device's operating system — we do not request precise GPS coordinates.
  • Before storing any location data, we snap coordinates to a grid of approximately 1.1 kilometres per cell (0.01° precision). This means we cannot determine your precise address, building, or street.
  • We store this coarse location in association with your account and with each post you create. It is used only to determine which posts appear in your feed.
  • Your location is never displayed to other users in the App.
  • We collect location each time the App opens or returns to the foreground.

Location permission is required to use Yapme. If you decline, the App will prompt you to enable it in your device settings — you will not be able to view or post to the feed until you do. You may revoke permission at any time in your device settings.

d) Push notification token

If you allow push notifications, your device generates a push token — a unique identifier used to deliver notifications to your device. We store this token on our servers. The token is deleted when you delete your account.

Push notification payloads contain: a title ("New reply"), a brief description ("@username replied to your post"), and the identifier of the relevant post. Push notifications never contain the content of posts.

e) Email verification codes

When you register or reset your password, we temporarily store a cryptographic hash (SHA-256) of your verification code. This hash is stored for a maximum of approximately one hour, after which it is automatically deleted.

f) Subscription information (Yapme+)

If you purchase a Yapme+ subscription, purchase processing is handled by Apple and by our subscription management provider RevenueCat. We receive and store:

  • Whether your subscription is currently active.
  • The subscription product and store (Apple App Store).
  • The start and expiry dates of your subscription.
  • A RevenueCat-assigned user identifier linked to your account.

We do not receive or store your payment card details. All payment processing is handled by Apple.

g) Moderation records

If another user reports a post you have created, we retain a record of that report. See Section 9 for details.

h) Technical information

Our infrastructure provider, Supabase, may log technical information in the ordinary course of operating the service, including IP addresses associated with requests to our servers. We do not actively collect or use IP address information for profiling or tracking. Please refer to Supabase's Privacy Policy for their data practices.

4. How We Collect Information

We collect information:

  • Directly from you when you register, post content, or change settings.
  • Automatically from your device when the App opens (location) or when events occur (push token registration).
  • From third-party providers when subscription events occur (RevenueCat webhook).

5. How We Use Your Information

Purpose Information used
Create and manage your account Email, username
Authenticate you Email (via Supabase Auth)
Show you geographically relevant posts Coarse location
Filter posts from users you have blocked or muted Account identifiers
Deliver push notifications about replies Push token
Manage your Yapme+ subscription Subscription records
Detect and act on abuse, harassment, and content that violates our Terms Report records, content
Send verification and password reset emails Email address
Comply with legal obligations As required

We do not use your information for advertising, profiling, or sale to third parties.

6. Disclosure to Third Parties

We disclose personal information to the following third parties to operate the App. All of these parties are located outside Australia (see Section 7).

Supabase, Inc. (United States)
Our core database and authentication infrastructure. All account data, post content, location data, push tokens, and application data are stored on Supabase's servers. Supabase Privacy Policy

RevenueCat, Inc. (United States)
Manages Yapme+ subscription state on iOS. We pass your account identifier to RevenueCat to link your subscription to your account. RevenueCat receives purchase receipt data from Apple. RevenueCat Privacy Policy

Resend, Inc. (United States)
Delivers verification code and password reset emails. Resend receives your email address and the content of those emails. Resend Privacy Policy

Expo (Expo Technology, Inc., United States)
Delivers push notifications to your device. Your push token is transmitted to Expo's servers when we send you a notification. Expo Privacy Policy

Apple Inc. (United States)
Processes in-app purchases for Yapme+ subscriptions. Subject to Apple's Privacy Policy. Apple Privacy Policy

We do not sell, rent, or trade your personal information to any other third party. We do not use advertising networks or data brokers.

7. Overseas Disclosure

All third-party providers listed in Section 6 are based in the United States. By using Yapme, you acknowledge that your personal information will be transferred to and processed in the United States.

We take reasonable steps to ensure these providers protect personal information in a manner consistent with the Australian Privacy Principles, including through contractual commitments.

8. Data Retention

Data Retention period
Post content Deleted after 24 hours
Replies Deleted when the associated post is deleted
Notifications Deleted when their associated post expires, and in any case within approximately 24 hours
Verification code hashes Deleted within approximately one hour of creation
Account information (email, username) Retained until you delete your account
Coarse location (last known, on account) Retained until you delete your account
Coarse location (per post) Deleted with the post after 24 hours
Push notification token Retained until you delete your account
Subscription records Retained until you delete your account
Blocks and mutes Retained until you delete your account
Moderation records (reports) See Section 9

9. Moderation Records

When a user reports a post, we store a record containing: the type of content reported, an internal identifier for the reported item, the reason provided, and the date of the report. This record is retained for moderation and safety purposes even if the reported content is subsequently deleted or expires.

When you delete your account:

  • Reports you have submitted are deleted (your identity as the reporter is removed).
  • Reports submitted about your posts are retained. After your account and posts are deleted, these records contain no personally identifying information — only an internal identifier for content that no longer exists, a reason category, and a date. They are kept solely for moderation history.

The app does not currently offer a mechanism to report user accounts directly. If that feature is added in future, any account-level report naming you would be deleted when you delete your account.

10. Account Deletion

You can delete your account at any time from Settings → Account → Delete account. When you delete your account:

  • Your account, username, and email address are permanently deleted.
  • All posts and replies you have created are permanently deleted.
  • Your approximate location data is permanently deleted.
  • Your push notification token is permanently deleted.
  • Your subscription record is permanently deleted.
  • All blocks and mutes you have created are permanently deleted.
  • Reports you have submitted are permanently deleted.
  • Reports submitted about your posts are retained in anonymised form as described in Section 9. They contain no name, email address, or account identifier after deletion.

Deletion is permanent and cannot be undone.

11. Security

We take reasonable steps to protect personal information from misuse, loss, and unauthorised access. These steps include encrypted communications (TLS), row-level security policies that restrict database access to the authenticated account holder, and access controls on our server infrastructure.

No method of electronic storage or transmission is completely secure. We cannot guarantee absolute security.

If we become aware of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.

12. Your Rights

Under the Privacy Act 1988, you have the right to:

  • Access the personal information we hold about you.
  • Correct personal information that is inaccurate, incomplete, or out of date.
  • Complain about our handling of your personal information.

To exercise these rights, contact us at privacy@yapme.com.au. We will respond within a reasonable period (generally 30 days).

13. Minimum Age

Yapme is intended for users aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with personal information, please contact us at privacy@yapme.com.au and we will take steps to delete that information.

14. Complaints

If you believe we have breached the Australian Privacy Principles, you may:

  1. Contact us first at privacy@yapme.com.au. We take complaints seriously and will respond within 30 days.
  2. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.

15. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will notify you through the App. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the App after changes are posted constitutes acceptance of the revised Policy.

16. Contact

Chidurala Technologies
Parramatta, New South Wales, Australia
privacy@yapme.com.au
© 2026 Chidurala Technologies Privacy policy Terms of service